CWE-347 · 799 records
Improper verification of cryptographic signature
Why does it happen?
The verifier takes the algorithm to verify with from the token’s own header. Untrusted data ends up deciding its own verification rule.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
const claims = jwt.verify(token, publicKey);Fixed
const claims = jwt.verify(token, publicKey, { algorithms: ["RS256"], issuer: "https://id.example.com", audience: "portal",});How to prevent it
- 01Pin the accepted algorithm on the server.
- 02Always validate the issuer (iss), audience (aud) and expiry (exp) claims.
- 03Don’t mix asymmetric and symmetric verification families on the same endpoint.
CVEs in this class
800 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2025-59718Weaponized | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Fortifortinet · fortiproxy · CWE-347 | Critical9.8 | KEV | 68.3% | Dec 9, 2025 |
73This week | CVE-2020-1464Weaponized | Windows Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-347 | High7.8 | KEV | 38.9% | Aug 17, 2020 |
71This week | CVE-2020-2021Weaponized | PAN-OS: Authentication Bypass in SAML Authenticationpaloaltonetworks · pan-os · CWE-347 | Critical10.0 | KEV | 4.4% | Jun 29, 2020 |
70This week | CVE-2026-48558Weaponized | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verificationsimple-help · simplehelp · CWE-347 | Critical9.5 | KEV | 5.7% | Jun 12, 2026 |
70This week | CVE-2026-5430Weaponized | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeoverwso2 · api control plane · CWE-347 | Critical10.0 | KEV | 0.6% | Aug 6, 2026 |
65This week | CVE-2013-3900Weaponized | WinVerifyTrust Signature Validation Vulnerabilitymicrosoft · windows 10 1507 · CWE-347 | Medium5.5 | KEV | 44.6% | Dec 10, 2013 |
57Plan | CVE-2025-25292No exploit | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Critical9.3 | — | 65.1% | Mar 12, 2025 |
55Plan | CVE-2021-22160No exploit | Authentication with JWT allows use of “none”-algorithmapache · pulsar · CWE-347 | Critical9.8 | — | 52.9% | May 26, 2021 |
51Plan | CVE-2018-16042No exploit | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earadobe · acrobat dc · CWE-347 | Medium6.5 | — | 82.4% | Jan 18, 2019 |
49Plan | CVE-2025-47827Weaponized | In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature.igel · igel os · CWE-347 | Medium4.6 | KEV | 4.9% | Jun 5, 2025 |
48Plan | CVE-2025-59719No exploit | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 tfortinet · fortiweb · CWE-347 | Critical9.8 | — | 29.2% | Dec 9, 2025 |
46Plan | CVE-2024-9487Proof of concept | An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassedgithub · enterprise server · CWE-347 | Critical9.5 | — | 25.6% | Oct 10, 2024 |
43Plan | CVE-2018-0114Proof of concept | A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens ucisco · node-jose · CWE-347 | High7.5 | — | 42.7% | Jan 4, 2018 |
43Plan | CVE-2025-25291Proof of concept | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Critical9.3 | — | 20.6% | Mar 12, 2025 |
42Plan | CVE-2024-45409Proof of concept | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Critical9.8 | — | 10.7% | Sep 10, 2024 |
41Plan | CVE-2021-37160No exploit | A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of softwarswisslog-healthcare · hmi-3 control panel firmware · CWE-347 | Critical9.8 | — | 8.2% | Aug 2, 2021 |
41Plan | CVE-2021-33885No exploit | An Insufficient Verification of Data Authenticity vulnerability in B.bbraun · spacecom2 · CWE-347 | Critical9.8 | — | 5.6% | Aug 25, 2021 |
40Plan | CVE-2025-29775Proof of concept | xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Commentnode-saml · xml-crypto · CWE-347 | Critical9.3 | — | 9.5% | Mar 14, 2025 |
40Plan | CVE-2025-29774Proof of concept | xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo Referencesnode-saml · xml-crypto · CWE-347 | Critical9.3 | — | 9.1% | Mar 14, 2025 |
40Plan | CVE-2018-12356No exploit | An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2.simple password store project · simple password store · CWE-347 | Critical9.8 | — | 4.6% | Jun 14, 2018 |
40Plan | CVE-2018-8955No exploit | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which albitdefender · gravityzone · CWE-347 | Critical9.8 | — | 4.3% | Oct 24, 2018 |
40Plan | CVE-2018-1000076No exploit | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-347 | Critical9.8 | — | 2.9% | Mar 13, 2018 |
40Plan | CVE-2019-6318No exploit | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an inshp · color laserjet cm4540 mfp firmware · CWE-347 | Critical9.8 | — | 2.6% | Apr 11, 2019 |
40Plan | CVE-2018-5923No exploit | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signaturehp · color laserjet cm4540 mfp firmware · CWE-347 | Critical9.8 | — | 2.6% | Mar 27, 2019 |
40Plan | CVE-2021-37927No exploit | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.zohocorp · manageengine admanager plus · CWE-347 | Critical9.8 | — | 2.2% | Sep 22, 2021 |
- CVE-2025-5971889Now
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Forti
CriticalCVSS 9.8KEVWeaponizedEPSS 68%fortinet · fortiproxyDec 9, 2025
- CVE-2020-146473This week
Windows Spoofing Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 39%microsoft · windows 10 1507Aug 17, 2020
- CVE-2020-202171This week
PAN-OS: Authentication Bypass in SAML Authentication
CriticalCVSS 10.0KEVWeaponizedEPSS 4%paloaltonetworks · pan-osJun 29, 2020
- CVE-2026-4855870This week
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
CriticalCVSS 9.5KEVWeaponizedEPSS 6%simple-help · simplehelpJun 12, 2026
- CVE-2026-543070This week
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
CriticalCVSS 10.0KEVWeaponizedEPSS 1%wso2 · api control planeAug 6, 2026
- CVE-2013-390065This week
WinVerifyTrust Signature Validation Vulnerability
MediumCVSS 5.5KEVWeaponizedEPSS 45%microsoft · windows 10 1507Dec 10, 2013
- CVE-2025-2529257Plan
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
CriticalCVSS 9.3No exploitEPSS 65%omniauth · omniauth samlMar 12, 2025
- CVE-2021-2216055Plan
Authentication with JWT allows use of “none”-algorithm
CriticalCVSS 9.8No exploitEPSS 53%apache · pulsarMay 26, 2021
- CVE-2018-1604251Plan
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and ear
MediumCVSS 6.5No exploitEPSS 82%adobe · acrobat dcJan 18, 2019
- CVE-2025-4782749Plan
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature.
MediumCVSS 4.6KEVWeaponizedEPSS 5%igel · igel osJun 5, 2025
- CVE-2025-5971948Plan
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 t
CriticalCVSS 9.8No exploitEPSS 29%fortinet · fortiwebDec 9, 2025
- CVE-2024-948746Plan
An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed
CriticalCVSS 9.5Proof of conceptEPSS 26%github · enterprise serverOct 10, 2024
- CVE-2018-011443Plan
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens u
HighCVSS 7.5Proof of conceptEPSS 43%cisco · node-joseJan 4, 2018
- CVE-2025-2529143Plan
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
CriticalCVSS 9.3Proof of conceptEPSS 21%omniauth · omniauth samlMar 12, 2025
- CVE-2024-4540942Plan
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
CriticalCVSS 9.8Proof of conceptEPSS 11%onelogin · ruby-samlSep 10, 2024
- CVE-2021-3716041Plan
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of softwar
CriticalCVSS 9.8No exploitEPSS 8%swisslog-healthcare · hmi-3 control panel firmwareAug 2, 2021
- CVE-2021-3388541Plan
An Insufficient Verification of Data Authenticity vulnerability in B.
CriticalCVSS 9.8No exploitEPSS 6%bbraun · spacecom2Aug 25, 2021
- CVE-2025-2977540Plan
xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
CriticalCVSS 9.3Proof of conceptEPSS 10%node-saml · xml-cryptoMar 14, 2025
- CVE-2025-2977440Plan
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
CriticalCVSS 9.3Proof of conceptEPSS 9%node-saml · xml-cryptoMar 14, 2025
- CVE-2018-1235640Plan
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2.
CriticalCVSS 9.8No exploitEPSS 5%simple password store project · simple password storeJun 14, 2018
- CVE-2018-895540Plan
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which al
CriticalCVSS 9.8No exploitEPSS 4%bitdefender · gravityzoneOct 24, 2018
- CVE-2018-100007640Plan
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
CriticalCVSS 9.8No exploitEPSS 3%rubygems · rubygemsMar 13, 2018
- CVE-2019-631840Plan
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an ins
CriticalCVSS 9.8No exploitEPSS 3%hp · color laserjet cm4540 mfp firmwareApr 11, 2019
- CVE-2018-592340Plan
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature
CriticalCVSS 9.8No exploitEPSS 3%hp · color laserjet cm4540 mfp firmwareMar 27, 2019
- CVE-2021-3792740Plan
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
CriticalCVSS 9.8No exploitEPSS 2%zohocorp · manageengine admanager plusSep 22, 2021